# Authlib signature verification bypass in JWS deserialization

Published: 2026-08-21 · Severity: routine · Sectors: technology, financial-services, government-national
Canonical: https://vorant.io/reports/6b49e1b3-9469-5ed8-8d0e-f033d56da643/authlib-signature-verification-bypass-in-jws-deserialization

> Authlib up to 1.7.2 accepts empty JWS signature arrays, allowing attackers to forge authentication tokens and bypass signature verification without key material.

Authlib, a widely-used Python library for OAuth, OpenID Connect, and JWT/JWS/JWE handling, contains a critical signature-verification bypass in its JSON Web Signature deserialization function. The JsonWebSignature.deserialize_json() method incorrectly treats JWS objects with empty "signatures" arrays as validly signed, allowing attackers to supply forged payloads without any cryptographic key material. Both JSON and compact JWS deserialization methods are affected. An attacker can exploit this to forge authentication tokens with arbitrary claims (identity, privilege escalation), inject malicious messages between microservices, forge authorization claims, or bypass integrity checks in systems relying on JWS verification. The vulnerability has been reported but no official patch was available at the time of the CERT/CC advisory publication. Affected organizations should monitor the Authlib GitHub repository for updates and upgrade immediately once a fix is released.

## Mentioned in this report

- Vulnerabilities: CVE-2026-96760

Source reporting: https://kb.cert.org/vuls/id/762428

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/6b49e1b3-9469-5ed8-8d0e-f033d56da643/authlib-signature-verification-bypass-in-jws-deserialization.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
